#VU1835 Cross-site scripting in Adobe Acrobat and Adobe Reader - CVE-2007-0048

 

#VU1835 Cross-site scripting in Adobe Acrobat and Adobe Reader - CVE-2007-0048

Published: December 21, 2016


Vulnerability identifier: #VU1835
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2007-0048
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Adobe Acrobat
Adobe Reader
Software vendor:
Adobe

Description

The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attack.

The vulnerability exists due to incorrect filtration of input data. A remote attacker can append specially URL containing a long sequence of # (hash) characters to PDF file, trick the victim into opening it, trigger memory corruption and cause the affected browser to crash.

Successful exploitation of this vulnerability results in denial of service on the vulnerable system.


Remediation


External links